
NCC Group Cybersecurity Consultant Interview Questions
& Process
Real candidates share what happened, how many rounds they had,
and how the experience turned out.
Based on 23 interview experiences · FREE TO READ
Candidate interview experiences
First-hand accounts from people who interviewed at NCC Group.
Cyber Security Consultant
I interviewed with NCC Group. The interview ended with a formal offer being made on the call. However, a week later, the TA manager called to say I was unsuccessful, which was shocking and disappointing.
No confirmed questions were included in this interview report.
Security Consultant
The hiring process, which lasted about two months from the first call to the offer, felt pretty smooth, even with holidays. The recruiter kept me updated and gave feedback on time. After the initial call, I had to do a web pentesting challenge. I submitted it twice because the first report wasn't detailed enough. It took about 3-4 weeks (due to holidays) to hear back that I passed and would move to the first interview. This interview was pretty chill; the interviewers were nice and asked about my background and some technical stuff. The next day, I found out I passed and was moving to the final interview. The second interview was more in-depth technically but still enjoyable. About a week later, I got the offer!
- Regarding the OWASP Top 10, can you walk me through a scenario with broken access and XSS, and what are the mitigation strategies?
- From the perspective of a regular domain user, describe the complete process of exploiting Active Directory.
- Could you explain the distinctions between the SYSTEM and Administrator accounts?
Security Consultant
I went to London for a couple of interviews and NCC was one of them. The first interview was a face-to-face talk with the Director to understand my goals and background. The second was a Web Application Penetration Test where a Lead consultant gave me a computer and asked me to demonstrate, step by step, how I usually perform a Web Application Pentest. For each vulnerability found, they asked about its criticality, impact, solution, and how to explore it. Then there was an infrastructure pentesting with the main goal of reaching domain admin. Almost the same questions were asked: Impact, how to explore, and 'what do you know about <insert-topic-here>'.
- Using the nbtscan output, how would you identify the Domain Controller.
NCC Group Cybersecurity Consultant Interview Questions
Quoted word for word from NCC Group interview reports.
“What are the mitigations for SSRF and where can they be found?”
Read reports →“Can you perform a penetration test on Mantis BT?”
Read reports →“Could you explain the distinctions between the SYSTEM and Administrator accounts?”
Read reports →“What are methods to bypass an anti-phishing solution?”
Read reports →“Can you detail the distinctions between encoding, hashing, and encryption?”
Read report →“Can you explain DOM XXS?”
Read report →“What are the definitions of constrained delegation, unconstrained delegation, and RBCD, and how do they differ from each other?”
Read report →“Can you reverse a protocol?”
Read report →“Can you explain XSS attacks?”
Read report →Formats, difficulty and experience
Across all 23 NCC Group interview reports.